Server Cookie Vulnerability in NLnet Labs Unbound Product Line
CVE-2026-54478
3.7LOW
What is CVE-2026-54478?
A vulnerability exists in NLnet Labs Unbound versions 1.18.0 to 1.25.1, where the server-cookie SipHash is computed over the proxy's wire address rather than the intended client. This flaw allows an off-path attacker to potentially harvest a valid server cookie from a single legitimate query and reuse it to bypass DNS Cookie checks, compromising the integrity and security of DNS responses. This vulnerability highlights significant risks in environments employing PROXYv2, necessitating prompt remediation.
Affected Version(s)
Unbound 1.18.0 < 1.25.2
